Total
397395 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-47875 | 1 Broadcom | 1 Spring Batch | 2026-09-02 | N/A | 5.6 MEDIUM |
| Applications that deserialize execution contexts with Jackson2ExecutionContextStringSerializer are vulnerable to a deserialization attack if they use an untrusted data source for the job repository. The JobParameterDeserializer does not properly enforce the trusted-types allowlist, allowing an attacker to craft malicious input that can lead to arbitrary code execution, including known Jackson RCE gadgets. Spring Batch 6.0.0 - 6.0.4 Spring Batch 5.2.0 - 5.2.6 | |||||
| CVE-2026-47877 | 1 Vmware | 1 Spring Security | 2026-09-02 | N/A | 8.2 HIGH |
| Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 | |||||
| CVE-2026-82909 | 2026-09-02 | 4.0 MEDIUM | 4.3 MEDIUM | ||
| A vulnerability was determined in QuantumNous new-api up to 1.0.0-rc.15. Affected by this issue is some unknown functionality of the file /api/usage/token/ of the component Revoked API Token Handler. Executing a manipulation can lead to session expiration. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.0.0-rc.17 can resolve this issue. This patch is called 0d5995eb63f8801d32eb32fbe74b75b68752bfa9. The affected component should be upgraded. | |||||
| CVE-2026-82852 | 2026-09-02 | N/A | 5.4 MEDIUM | ||
| Unauthenticated Server Side Request Forgery (SSRF) in MapSVG <= 8.15.0 versions. | |||||
| CVE-2026-82834 | 2026-09-02 | 5.5 MEDIUM | 5.4 MEDIUM | ||
| A security flaw has been discovered in Doccano Open Source Annotation Tools for Machine Learning Practitioners and Auto Labeling Pipeline Module to Annotate a Document Automatically up to 1.8.5. This affects the function LabelList of the file /v1/projects/1/category-types of the component Bulk-Delete Endpoint. Performing a manipulation results in improper access controls. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | |||||
| CVE-2026-82817 | 2026-09-02 | 6.5 MEDIUM | 6.3 MEDIUM | ||
| A vulnerability was found in dibo-software diboot 3.8.0. Affected by this issue is some unknown functionality of the file /admin/ of the component Tenant Administrator Management API. Performing a manipulation of the argument tenantId results in improper access controls. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. | |||||
| CVE-2026-82810 | 2026-09-02 | 1.7 LOW | 3.3 LOW | ||
| A weakness has been identified in extension.vn 2FA Authenticator Extension 1.0.0.2 on Chrome. The impacted element is the function chrome.runtime.onMessageExternal.addListener of the component Background Service Worker. Executing a manipulation of the argument sender.id can lead to information disclosure. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure. | |||||
| CVE-2026-81756 | 2026-09-02 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions. | |||||
| CVE-2026-81291 | 2026-09-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Uncode <= 2.12.7 versions. | |||||
| CVE-2026-73709 | 1 Arubanetworks | 1 Fabric Composer | 2026-09-02 | N/A | 8.3 HIGH |
| A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an unauthenticated adjacent attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. | |||||
| CVE-2025-13398 | 2026-09-02 | N/A | N/A | ||
| Rejected reason: This CVE ID is a duplicate of CVE-2025-13542 and was never published. Both IDs were assigned to the same unauthenticated privilege escalation vulnerability in the DesignThemes LMS WordPress plugin. All CVE users should reference CVE-2025-13542 instead of this ID. | |||||
| CVE-2026-73744 | 1 Arubanetworks | 1 Fabric Composer | 2026-09-02 | N/A | 3.5 LOW |
| A denial-of-service vulnerability exists in the web-based management interface of HPE Networking Fabric Composer that could allow an authenticated low privilege operator user to cause a denial of service. Successful exploitation could allow an attacker to disrupt the availability of the affected interface. | |||||
| CVE-2026-73746 | 1 Arubanetworks | 1 Fabric Composer | 2026-09-02 | N/A | 3.1 LOW |
| A denial-of-service vulnerability exists in the API of HPE Networking Fabric Composer that could allow an authenticated low privilege operator user to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service. | |||||
| CVE-2026-73747 | 1 Arubanetworks | 1 Fabric Composer | 2026-09-02 | N/A | 2.5 LOW |
| A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user with local access to elevate their user privileges and make limited modifications on the affected system. | |||||
| CVE-2026-76657 | 1 Arubanetworks | 1 Fabric Composer | 2026-09-02 | N/A | 10.0 CRITICAL |
| Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the HPE Networking Fabric Composer host. | |||||
| CVE-2026-73748 | 1 Arubanetworks | 1 Fabric Composer | 2026-09-02 | N/A | 2.2 LOW |
| A vulnerability in the affected interface of HPE Networking Fabric Composer allows an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking Fabric Composer. | |||||
| CVE-2026-18549 | 1 Fastify | 1 Fastify-multipart | 2026-09-02 | N/A | 7.5 HIGH |
| @fastify/multipart is a multipart form-data parser for Fastify. In versions from 5.3.0 up to but not including 10.1.1, when the busboy fileSize limit truncates a file part, the plugin clears its internal current-file reference while the underlying stream is still open. If the client then aborts the connection before sending the terminating boundary, the abort cleanup finds no stream to destroy, so saveRequestFiles() never settles, the request handler hangs, and the temporary file already written to disk is never cleaned up. An unauthenticated client can repeat this to permanently leak temporary files and suspended handler executions, leading to disk and event-loop exhaustion. The issue is fixed in @fastify/multipart 10.1.1. Users should upgrade to 10.1.1. | |||||
| CVE-2026-76658 | 1 Arubanetworks | 1 Fabric Composer | 2026-09-02 | N/A | 10.0 CRITICAL |
| A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system leading to complete system compromise. | |||||
| CVE-2026-19474 | 1 Fastify | 1 Fastify-multipart | 2026-09-02 | N/A | 7.5 HIGH |
| @fastify/multipart is a multipart form-data parser for Fastify. In versions from 3.0.0 up to but not including 10.1.1, request.saveRequestFiles() can leave completed temporary files on disk when a client disconnects while the parser is advancing between multipart parts. The iterator rejection that occurs between parts falls outside the per-file cleanup path, so an earlier completed file is never removed. An unauthenticated client can repeat this to cause persistent, linear disk consumption, leading to denial of service. This is an incomplete-fix variant of CVE-2025-24033. The issue is fixed in @fastify/multipart 10.1.1. Users should upgrade to 10.1.1. | |||||
| CVE-2026-24183 | 1 Nvidia | 1 Cumulus Linux | 2026-09-02 | N/A | 7.8 HIGH |
| NVIDIA Cumulus Linux contains a vulnerability in the user management component, where an unprivileged user could use improper privilege management on the system. A successful exploit of this vulnerability might lead to escalation of privileges. | |||||
